Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-5076
HistoryJun 29, 2012 - 12:00 a.m.

CVE-2010-5076

2012-06-2900:00:00
ubuntu.com
ubuntu.com
14

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

55.7%

QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the
subject’s Common Name field of an X.509 certificate, which might allow
man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted
certificate issued by a legitimate Certification Authority.

Notes

Author Note
jdstrand Ubuntu 11.04 and higher not affected
OSVersionArchitecturePackageVersionFilename
ubuntu10.04noarchqt4-x11< 4:4.6.2-0ubuntu5.4UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

55.7%